Privacy Policy

1. Privacy Statement

1.1. GetOnline Ltd trading as 'AuthSMTP' (the "Vendor") operates https://www.authsmtp.com (the "Website").

1.2. This page informs you (the "Visitor") of the Vendor policies regarding the collection, use and disclosure of Personal Information that is received from Visitors of the Website and via other communication channels such as email or physical mail, where no formal agreement exists between the Vendor and the Visitor.

1.3. The primary purpose of the Website is to advertise the Service which is an authenticated SMTP relay server along with other ancillary websites and functions (the "Service").

1.4. The Vendor will use Personal Information provided by the Visitor to operate and personalise the Website, respond to enquiries and provide information about the Service. The Vendor will not sell the Visitor's Personal Information. Information may be processed by service providers acting on the Vendor's behalf where necessary to deliver, protect and analyse the Website, respond to enquiries or comply with legal obligations.

1.5. Should the Visitor enter into an agreement with the Vendor to use the Service, the agreement will be subject to the Terms of Service and the separate Service Privacy Policy.

2. Eligibility to use the Website

2.1 By using the Website, the Visitor agrees to the collection and use of information in accordance with this policy.

2.2 Under no circumstances should the Visitor provide the Vendor with any information that would be classed as Sensitive Personal Information as defined in article 9 of the GDPR regulations, this includes (but is not limited to) any of the following:

  • a. Race
  • b. Ethnic origin
  • c. Political views
  • d. Religious views
  • e. Trade union membership
  • f. Genetic data
  • g. Biometric data
  • h. Health data
  • i. Sexual orientation

2.3. The Service is primarily a business to business service, to be eligible to use the Website and the Service the Visitor must be aged 18 or over.

3. Information Collection, Use and Retention (Website)

3.1. The Website is delivered and protected using Cloudflare's network and services. Cloudflare may process technical request, traffic and security data, including IP addresses, request metadata and security signals, as necessary to deliver and protect the Website.

3.1.1. Website requests may be processed through Cloudflare infrastructure outside the United Kingdom. Cloudflare processes relevant Customer Logs and website content on behalf of the Vendor under its applicable contractual and data-protection terms.

3.2. Information submitted through the Website's contact forms is processed by a Cloudflare Worker, temporarily stored in Cloudflare R2 object storage currently located in Western Europe for a maximum of 90 days, and sent to the Vendor's support email system in the United Kingdom.

3.2.1. The contact forms use Cloudflare Turnstile to distinguish legitimate visitors from automated submissions. Turnstile processes security signals for this purpose.

3.3. The Visitor may select a preferred billing currency. This preference is stored in a secure browser cookie for seven days. The Website does not use or retain the Visitor's geographic location to select a currency.

3.4. Depending on the type of enquiry, the Website may request the following information:

  • Full Name
  • Contact and Alternative Email Addresses
  • AuthSMTP Account Number
  • Enquiry Information
  • Message Headers and Comments

3.5. Temporary contact-form copies stored in Cloudflare R2 are deleted after a maximum of 90 days. Enquiries transferred to the Vendor's support system, including subsequent replies, may be retained for a maximum of 3 years and 1 month.

3.6. If the Visitor chooses to receive marketing emails, they have the option of opting out at any time via the email links provided.

3.7. The Vendor will never ask for, and the Visitor should never offer the following information:

  • a. Sensitive Personal Information
  • b. Account Passwords

4. Information Collection, Use and Retention (Direct Email)

4.1. The primary email service for direct messages to authsmtp.com is hosted on a private email server in the United Kingdom.

4.2. If the Visitor sends a direct email message, the Vendor will store the full message itself, any subsequent replies and the related log data for a maximum of 3 years and 1 month and then they will be deleted.

4.3. The Vendor will never ask for, and the Visitor should never offer the following information:

  • a. Sensitive Personal Information
  • b. Account Passwords

5. Information Collection, Use and Retention (Other)

5.1. The primary channels of communication are via email and the Website, communication via other channels such as telephone or the physical postal services are not offered.

5.2. Any unsolicited communication received via these other channels will have the same privacy policies applied as our primary communication channels wherever possible.

6. Log Data

6.1. Like many website operators, the Vendor will automatically collect information from the Visitor's browser whenever they visit the Website (the "Log Data").

6.2. This Log Data may include information such as the computer's Internet Protocol ("IP") address, browser type, browser version, the pages of the Website that were visited, the time and date of the visit, the time spent on those pages and other statistics.

6.3. In addition, the Vendor may use third-party services such as Google Analytics to collect, monitor and analyse Website activity. These providers process information on behalf of the Vendor under their applicable contractual and data-protection terms.

6.4. Log data will be stored for a maximum of 6 years and 1 month.

7. Data Transfers, Sharing and Disclosure

7.1. The Vendor will not sell the Visitor's Personal Information. Information may be disclosed to contracted service providers, including Cloudflare and website analytics providers, where necessary to operate, secure and analyse the Website or respond to enquiries.

7.2. Technical request, traffic and security data may be processed outside the United Kingdom through Cloudflare's global network.

7.3. Contact-form submissions are temporarily stored using Cloudflare R2 in Western Europe and transferred to the Vendor's support email system in the United Kingdom.

7.4. Where information is processed outside the United Kingdom, the Vendor will use appropriate contractual and data-protection safeguards.

8. Cookies

8.1. Cookies are files containing a small amount of data, which may include an anonymous unique identifier. Cookies are sent to the browser from a website and stored on the computer's hard drive.

8.2. Like many sites, the Vendor uses "cookies" to collect information. A Visitor can instruct their browser to refuse all cookies or to indicate when a cookie is being sent. However, if the Visitor does not accept cookies, they may not be able to use some portions of the Website.

9. Security

9.1. The security of Personal Information is of upmost importance but it should be noted that no method of transmission over the Internet, or method of electronic storage, is 100% secure. While the Vendor strives to use commercially acceptable means to protect Personal Information, the Vendor cannot guarantee its absolute security.

10. Consent

10.1. By using the Website, the Visitor agrees to the collection and use of information in accordance with this policy.

10.2 If the Visitor provides additional Personal Information described in section 3 of this document, further consent will be sought before the information can be submitted.

10.3. To withdraw consent the Visitor should cease accessing the Website and remove any related cookies.

10.4. For information on how to remove cookies please visit https://cookiesandyou.com.

11. Data Access Request

11.1. To request a copy of any information that the Vendor holds in connection with a Visitor name and email address, please visit:

Data Subject Access Request

12. Data Deletion Request

12.1. To request deletion of any information that the Vendor holds in connection with a Visitor name and email address, please visit:

Data Deletion Access Request

13. Contact

13.1. For any questions about this policy, please contact the Vendor data protection team using the email address [email protected].

14. Changes to this policy

14.1. This policy is effective as of the 25th of May 2018 and will remain in effect except with respect to any changes in its provisions in the future, which will be in effect immediately after being posted on this page.

14.2. The Vendor reserves the right to update or change the policy at any time and the Visitor should check this policy periodically. The continued use of the Website after the Vendor posts any modifications to the policy on this page will constitute the Visitors acknowledgment of the modifications and consent to abide and be bound by the modified policy.

14.3. If the Vendor make any material changes to the policy, the Vendor will notify by placing a prominent notice on the Website.

15. Current Version

15.1. The version reference for this website privacy policy is:

WPP-1.0.1